On August 4, 2026, the IRS and its Security Summit partners issued a formal warning to tax professionals and business owners about an active wave of phishing emails and related schemes designed to steal sensitive taxpayer data. The warning is not theoretical. These attacks are occurring right now, and retail and CPG businesses are among the targets. The schemes exploit two things that make businesses vulnerable: the volume of financial communications that controllers and business owners process daily, and the urgency that the word IRS tends to create when it appears in a subject line.
Phishing schemes targeting business tax data typically take one of several forms. The most common is an email that appears to come from the IRS, a tax software company, or a payroll provider, informing the recipient of a problem with their account, a pending audit, an overdue balance, or a tax refund that requires immediate action. The email includes a link or an attachment. Clicking the link takes the recipient to a convincing-looking fake website designed to capture login credentials, EIN numbers, banking information, or Social Security numbers. Opening the attachment installs malware that can capture keystrokes or gain access to stored financial files.
How to identify a phishing attempt targeting business tax information, and what to do if you receive one.
Retail and CPG businesses are particularly attractive targets for tax-related phishing because they process high volumes of financial transactions, employ large numbers of people whose payroll data is valuable, and often have multiple people with access to accounting systems and tax filing credentials. Controllers and accounts payable staff, who are accustomed to receiving and acting on financial communications quickly, are high-value targets precisely because of their training to be responsive. Brief your team on what legitimate IRS communication looks like and establish a clear protocol for what to do when something feels suspicious.
The practical rule is simple. The IRS will never initiate contact with your business by email, text message, or social media. Every legitimate IRS communication begins with a letter delivered by postal mail with a notice number, a phone number to call, and a deadline to respond. If you receive anything that claims to be from the IRS through any other channel, treat it as suspicious and verify it through IRS.gov before taking any action.
Bottom Line: If you receive an unexpected email, text, or call claiming to be from the IRS, do not engage with it. The IRS contacts businesses by mail. Forward suspicious emails to phishing@irs.gov, hang up on suspicious calls, and brief your finance and payroll teams on what a real IRS communication looks like. One click on a phishing link can compromise your entire tax filing and payroll infrastructure.




